CVE-2005-1264

Linux kernel 2.6.x - Use After Free

Title source: llm
STIX 2.1

Description

Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10264
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0557
Exploit, Patch, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0045.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13651
Third Party Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0046.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-420.html
Third Party Advisory, VDB Entry vendor-advisory x_refsource_fedora
http://www.securityfocus.com/archive/1/427980/100/0/threaded
Mailing List mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=111630512512222

Scores

EPSS 0.0053
EPSS Percentile 42.3%

Details

Status published
Products (11)
linux/linux_kernel 2.6.0 (12 CPE variants)
linux/linux_kernel 2.6.1 (3 CPE variants)
linux/linux_kernel 2.6.2
linux/linux_kernel 2.6.3
linux/linux_kernel 2.6.4
linux/linux_kernel 2.6.5
linux/linux_kernel 2.6.6 (2 CPE variants)
linux/linux_kernel 2.6.7 (2 CPE variants)
linux/linux_kernel 2.6.8 (4 CPE variants)
linux/linux_kernel 2.6.9 2.6.20
... and 1 more
Published May 17, 2005
Tracked Since Feb 18, 2026